Skip to main content
POST
Mint an impersonation token for a user

Body

application/json

Represents a request to mint an impersonation token for a user on behalf of the calling app. The app authenticates with its own service-account token in the Authorization header (identified by its urn:jtl:app_id claim); no user token is needed.

userId
string
required

Gets or sets the Zitadel user id to impersonate (the subject of the minted token).

Minimum string length: 1
tenantId
string
required

Gets or sets the tenant to act in. The app must be installed for it and the user must be a member of it; the minted token is stamped with this tenant.

Minimum string length: 1

Response

The user-subject access token, its refresh token and lifetime.

Represents the response for a minted on-behalf-of-user token.

accessToken
string

Gets the user-subject access token minted for the calling app.

refreshToken
string | null

Gets the refresh token for rotating the access token for unattended, long-running access.

expiresIn
number<double>

Gets the access token lifetime in seconds.